Splunk Search

How to overlay or mark a chart based on column value?

Loves-to-Learn Lots

Hi all,

I have a chart displaying 3 line charts based on our test results. Now we would like to show the test start and end timings like a marker on the _time in the x - axis like a vertical marker or something like that saying when the test has been started and ended.

alt text

Here is my second search:

index=gc sourcetype=gc_analysis  |table _time test_status |where test_status!="null"

Is it possible to mark the above chart with the field test_status marking the x - axis when the test has been started and ended.


0 Karma

Esteemed Legend

Yes, this is a relatively new feature called Event Annotations:

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...